A recent report has highlighted the alarming rise in deepfake incidents, revealing that three-quarters of cybersecurity leaders have encountered suspected deepfake attacks in the past year. The Pindrop Deepfake Readiness Index, published on September 28, underscores a troubling gap between the threat posed by deepfakes and the readiness of enterprises to counter them. Deepfakes, which are AI-generated audio and video designed to mimic real people, have become an increasingly sophisticated tool in the arsenal of cybercriminals. They are often used to impersonate colleagues or executives, leading to fraudulent financial transactions or the sharing of sensitive information.

According to the survey, 74% of over 250 US security leaders reported encounters with deepfakes, with 25% experiencing financial losses exceeding $1 million from a single incident. The costs associated with these attacks include direct financial losses, incident remediation, and the diversion of time and resources to address the threat. Despite these substantial financial impacts, there remains a concerning lack of awareness at the board level. Many security leaders believe it would take a leader being impersonated by a deepfake for the issue to gain the necessary attention.

The report also found that 93% of security leaders are concerned about their organization's preparedness to face deepfake threats. Elie Khoury from Pindrop emphasized that attackers exploit the trust placed in familiar faces and voices, turning these into vulnerabilities. Enterprises are urged to apply the same security rigor to human interactions as they do to systems and devices. A report by Gartner also suggests that CISOs update their strategies to address the sophisticated nature of deepfakes. Recommended countermeasures include staff training, implementing phishing-resistant controls like MFA, and vigilance against suspicious communications.